
Malwarebytes warns of scams where fake AML services trick crypto users into connecting wallets, risking asset theft by approving malicious transactions.
AI-generated summary
Crypto scams have been on the rise, with various tactics employed to steal user assets.
Scammers are targeting crypto holders with fake anti-money laundering services designed to trick users into approving transactions that could put their digital assets at risk, cybersecurity firm Malwarebytes warned. In a report published Wednesday, Malwarebytes said the sites impersonate services that check whether crypto wallets have interacted with stolen or illicit funds. Some mimic the legitimate service AMLBot, while others use generic names such as “AML Check.” Crypto AML services check a wallet's public transaction history for links to hacks, scams, sanctioned entities, and other suspicious activity. A basic check only requires a wallet's public address and does not require users to connect their wallet, approve permissions, or sign a transaction. According to Malwarebytes, the fake sites prompt users to connect their crypto wallets for an AML check, then simulate the process with fake progress messages and results. One site asked users for a small top-up to cover a supposed fee before returning a “Clean, Low Risk” result, regardless of whether a genuine check occurred. “If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign,” Malwarebytes researchers wrote. Connecting a wallet alone does not allow scammers to steal funds, but it reveals the wallet's public address, which lets them see its assets and create a transaction for the victim to approve. Malwarebytes found the same basic design and process under several names and logos, suggesting the scam template is being reused and rebranded. Seasoned crypto users are no strangers to these types of ploys, but lately there’s been a series of phishing campaigns using fake websites to target crypto holders. Earlier this month, hardware wallet makers Trezor and Foundation warned of phishing emails directing users to a cloned Coldcard website, while in March, Malwarebytes uncovered a fake version of Pudgy Penguins’ Pudgy World game designed to steal wallet passwords. That same month, crypto exchange CoinDCX said it had identified more than 1,200 websites impersonating its platform between April 2024 and January 2026. Malwarebytes advised users who approved token access to revoke suspicious permissions. Users who entered a recovery phrase or private key should consider the wallet compromised and move their assets to a new wallet. “Crypto transactions generally can’t be reversed once they’re confirmed, so acting quickly matters if you’ve approved something suspicious,” Malwarebytes said.
AI outlook — possibilities, not facts
Increased reports of crypto scams as awareness grows.
Likely · Within weeks

MANTRA Chain halted its mainnet on Aug. 21 after an attacker exploited an upstream dependency. Transactions, staking, and transfers are currently suspended while the team tests a security patch on the DuKong testnet before a coordinated restart.

Solana has successfully reduced its slot time to 350 milliseconds, down from 400ms, as part of a multi-stage plan to improve network latency. The update, approved via SIMD-0525, aims for further reductions toward a 200ms target.

Ethereum's better.codes contest tracks a 52.14-bit cryptographic proof gap for the koalaIRS12 parameter profile, measuring distance between certified safety and unsafe bounds via soundness and attack tracks.

Coldcard maker Coinkite released a security overhaul for Bitcoin hardware wallets following a firmware flaw that led to over $130 million in stolen Bitcoin.

Solana has upgraded its network for the first time since genesis, reducing base slot timing from 400ms to 350ms to speed up transaction confirmations. The change is part of a phased plan to reach 200ms, aiming to improve latency and censorship resistance.

A Bitcoin address tied to Maya Protocol's Aug. 18 exploit still held ~20.8 BTC worth $1.59M on Aug. 21, as technical analyses reveal broader pool damage exceeding initial estimates and recovery plans remain undefined.